Welcome, Guest. Please login or register.
October 13, 2008, 05:21:31 PM

Login with username, password and session length

199987 Posts
22956 Topics
55076 Members

Latest Member: superpuppet

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Want to help Comodo?
| |-+  Please tell us your views and Vote here!
| | |-+  Security in the forum
« previous next »
Pages: [1] Go Down Print
Author Topic: Security in the forum  (Read 2718 times)
Martin.H
Guest
« on: December 13, 2007, 02:33:55 AM »

You're dealing with internet-security?
Why do you send me my password in an unsecure email if I don't ask you for this???
Can't you imagine that I don't use a seperate password for each forum?
We're living in 2007 and the internet wasn't made up yesterday.
If you got such obvious security-problems, I don't want to think about what's happening with the rest of my personal data on your servers.

Best regards
Bye
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3181


bubble!


« Reply #1 on: December 13, 2007, 08:45:42 AM »

Huh i think this guy is more paranoid than me  Tongue
Logged

pierceive
Newbie
*
Offline Offline

Posts: 5


« Reply #2 on: December 15, 2007, 07:45:40 PM »

I just came here to post exactly what the OP said. Sending passwords in cleartext is a great indicator of a complete lack of security (and I generally try to avoid doing business with any such sites). This has nothing to do with paranoia; it is a huge security risk to any and all users. There is no reason that my password should be stored anywhere but in my head or in an encrypted database.
Logged
CGPMaster
United States Marine
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 689


"Honor, Courage, Commitment" - USMC


« Reply #3 on: December 15, 2007, 07:58:47 PM »

Huh i think this guy is more paranoid than me  Tongue


I agree, lol... but also i see, The Reason for being such Hiped up by just a forum password....So Much info you can get ....idk  -cg
Logged

Semper Fi!
Call Me CG Not CGP
3.0 GHZ (AMD)
5GB Ram
12TB Of HD
WinXP Pro+WinXP Vista+LinJJS+LinFedora
20090616 USMCRD PI Ooh-Rah
Law Of The Land(Forum)
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3181


bubble!


« Reply #4 on: December 16, 2007, 10:16:05 PM »

I just came here to post exactly what the OP said. Sending passwords in cleartext is a great indicator of a complete lack of security (and I generally try to avoid doing business with any such sites). This has nothing to do with paranoia; it is a huge security risk to any and all users. There is no reason that my password should be stored anywhere but in my head or in an encrypted database.
it's just forum password, we shouldn't use single password for forum,email, and internet banking. who wants to steal a forum password anyway  Tongue
Logged

gordon
Comodo's Hero
*****
Offline Offline

Posts: 245



« Reply #5 on: December 17, 2007, 07:47:03 AM »

Many boards send you your password by e-mail, f.ex if you forgot it, as a service..
usually they also tell you that the first thing you should do is change it ! ..
.. over SSL (HTTPS) of course Smiley
and you shouldn't be using the same password for multiple accounts because there are punks who try to steal passwords and/or crack accounts, God knows why ...

By default EVERYTHING you send over the internet is in clear-text
and can be read by anyone with access to the wires, that's just how networking was designed ..
E-mails are like a postcard, all you need to read them is access .

You can use GPG  http://www.gnupg.org/
to encrypt your E-mail but it requires that sender and receiver both have it installed
and it requires key-management,passphrases etc etc ..

Theres a GPG-extension for Thunderbird available,
it works very well and is relatively simple to set up
https://addons.mozilla.org/en-US/thunderbird/addon/71

Use a password-manager like KeePass  http://keepass.info/
it also has a password-generator,that way you can have unique log-ins for each account
and only need to remember one master-password .
Your log-ins are stored in a 256bit AES encrypted database .

   
 

 
« Last Edit: December 17, 2007, 07:54:08 AM by gordon » Logged

andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 630


« Reply #6 on: December 18, 2007, 10:31:31 PM »

Many boards send you your password by e-mail, f.ex if you forgot it, as a service..
usually they also tell you that the first thing you should do is change it ! ..
.. over SSL (HTTPS) of course Smiley
and you shouldn't be using the same password for multiple accounts because there are punks who try to steal passwords and/or crack accounts, God knows why ...

By default EVERYTHING you send over the internet is in clear-text
and can be read by anyone with access to the wires, that's just how networking was designed ..
E-mails are like a postcard, all you need to read them is access .

You can use GPG  http://www.gnupg.org/
to encrypt your E-mail but it requires that sender and receiver both have it installed
and it requires key-management,passphrases etc etc ..

Theres a GPG-extension for Thunderbird available,
it works very well and is relatively simple to set up
https://addons.mozilla.org/en-US/thunderbird/addon/71

Use a password-manager like KeePass  http://keepass.info/
it also has a password-generator,that way you can have unique log-ins for each account
and only need to remember one master-password .
Your log-ins are stored in a 256bit AES encrypted database .

   
 

 

<<<Uses Opera which has a highly secure password manager built in  Wink
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.143 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com